M365Pwned – Red Team GUI Toolkit for Microsoft 365 Exploitation via Graph API
ID: 5a258dd3-e28f-5d4b-bd51-864aff2969b5
STIX ID: report--5a258dd3-e28f-5d4b-bd51-864aff2969b5
Feed Name: cybersecurityNews.com
Threat Score
**M365Pwned — Red Team GUI Toolkit:** A PowerShell 5.1 WinForms toolkit (MailPwned and SharePwned) that uses admin-consented Azure AD application permissions and the Microsoft Graph API to enumerate tenant mailboxes and SharePoint/OneDrive drives, perform tenant-wide searches, preview and download content, compose impersonation emails, and enable bulk exfiltration; defenders are advised to audit application permissions, consent grants, and anomalous Graph API usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
